StarRocks configuration parameters

To configure the service, use the following configuration parameters in ADCM.

NOTE
  • Some of the parameters become visible in the ADCM UI after the Advanced flag has been set.

  • Parameters related to Ranger configuration files are populated or initialized automatically during the ADPS and ADH cluster integration process prior to enabling the StarRocks Ranger plugin. Do not modify these parameters manually unless explicitly required by the configuration procedure.

  • The parameters that are set in the Custom group will overwrite the existing parameters even if they are read-only.

Credentials
Parameter Description Default value

Service user

Service user account name. It is preconfigured with the cluster_admin role and no table or data access

service_user

Service user password

Service user account password

 — 

LDAP authentication
Parameter Description Default value

authentication_ldap_simple_server_host

LDAP server hostname or IP address

 — 

authentication_ldap_simple_server_port

LDAP server port

 — 

authentication_ldap_simple_bind_root_dn

Distinguished Name (DN) of the LDAP account used to bind to the LDAP server

 — 

authentication_ldap_simple_bind_root_pwd

Password of the LDAP account used to bind to the LDAP server

 — 

authentication_ldap_simple_bind_base_dn

Base Distinguished Name (DN) from which StarRocks searches for user accounts

 — 

authentication_ldap_simple_user_search_attr

LDAP attribute used to search for a user account. Typically, this is the uid attribute

 — 

authentication_ldap_simple_ssl_conn_allow_insecure

Specifies whether StarRocks allows insecure SSL connections to the LDAP server without verifying the server certificate

 — 

authentication_ldap_simple_ssl_conn_trust_store_path

Path to the trust store containing the certificates trusted for SSL connections to the LDAP server

 — 

authentication_ldap_simple_ssl_conn_trust_store_pwd

Password for the trust store used to verify the LDAP server certificate

 — 

FE MySQL SSL
Parameter Description Default value

ssl_keystore_location

Path to the keystore containing the SSL certificate and private key

 — 

ssl_keystore_password

Password for the SSL keystore

 — 

ssl_key_password

Password for the private key stored in the SSL keystore

 — 

ssl_force_secure_transport

Specifies whether StarRocks requires secure transport for client connections

 — 

ranger-starrocks-security.xml
Parameter Description Default value

ranger.plugin.starrocks.service.name

Name of the StarRocks service in Apache Ranger

<ADH_cluster_name_normalized>_starrocks_id_<number>

ranger.plugin.starrocks.policy.rest.url

URL of the Apache Ranger Policy Manager REST API

http://<Ranger host name>:6080

ranger.plugin.starrocks.policy.rest.ssl.config.file

Path to the SSL configuration file used for connecting to the Apache Ranger Policy Manager

/etc/starrocks/fe/conf/ranger-policymgr-ssl.xml

ranger.plugin.starrocks.policy.pollIntervalMs

Interval in milliseconds between StarRocks policy synchronization requests to Apache Ranger

30000

ranger-starrocks-audit.xml
Parameter Description Default value

xasecure.audit.is.enabled

Enables Ranger audit

true

xasecure.audit.solr.is.enabled

Specifies whether audit events are sent to Apache Solr

true

xasecure.audit.solr.solr_url

URL of the Apache Solr server used to store StarRocks audit events

http://<Solr host name>:8983/solr/ranger_audits

xasecure.audit.hdfs.is.enabled

Specifies whether audit events are stored in HDFS

false

xasecure.audit.hdfs.config.destination.directory

HDFS directory where StarRocks audit events are stored

 — 

xasecure.audit.destination.solr

Specifies whether Solr is enabled as an audit event destination

true

xasecure.audit.destination.solr.urls

Comma-separated list of Solr server URLs used as audit event destinations. Leave this property value empty or set it to NONE when using ZooKeeper to connect to Solr

 — 

xasecure.audit.destination.solr.batch.filespool.dir

Local directory used to spool audit events before they are sent to Solr

/srv/ranger/starrocks_plugin/audit_solr_spool

xasecure.audit.destination.solr.force.use.inmemory.jaas.config

Specifies whether StarRocks uses an in-memory JAAS configuration for authentication to Solr

false

xasecure.audit.jaas.Client.loginModuleName

Name of the JAAS login module used to authenticate the StarRocks audit client

 — 

xasecure.audit.jaas.Client.loginModuleControlFlag

JAAS control flag that determines how the login module affects authentication

 — 

xasecure.audit.jaas.Client.option.keyTab

Path to the Kerberos keytab file used by the audit client

 — 

xasecure.audit.jaas.Client.option.principal

Kerberos principal used by the audit client for authentication

 — 

xasecure.audit.jaas.Client.option.serviceName

Kerberos service name used by the audit client

 — 

xasecure.audit.jaas.Client.option.useKeyTab

Specifies whether the audit client uses a Kerberos keytab for authentication

false

xasecure.audit.jaas.Client.option.storeKey

Specifies whether the audit client stores the Kerberos key in the subject credentials

false

ranger-policymgr-ssl.xml
Parameter Description Default value

xasecure.policymgr.clientssl.keystore

Path to the SSL keystore used by StarRocks to authenticate with the Ranger Policy Manager

/etc/ssl/keystore.jks

xasecure.policymgr.clientssl.truststore

Path to the SSL truststore used by StarRocks to verify the Ranger Policy Manager certificate

/etc/ssl/truststore.jks

xasecure.policymgr.clientssl.keystore.credential.file

Path to the credential file containing the password for the SSL keystore used by StarRocks to authenticate with the Ranger Policy Manager

/etc/starrocks/fe/conf/ranger-starrocks.jceks

xasecure.policymgr.clientssl.truststore.credential.file

Path to the credential file containing the password for the SSL truststore used by StarRocks to verify the Ranger Policy Manager certificate

/etc/starrocks/fe/conf/ranger-starrocks.jceks

Other
Parameter Description Default value

Ranger plugin

Enables (true) or disables (false) the Ranger plugin

false

Custom ranger-starrocks-security.xml

In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-starrocks-security.xml

 — 

Custom ranger-starrocks-audit.xml

In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-starrocks-audit.xml

 — 

Custom ranger-policymgr-ssl.xml

In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-policymgr-ssl.xml

 — 

starrocks-java.yaml

In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-policymgr-ssl.xml

 — 

starrocks-java.yaml

The contents of the starrocks-java.yaml Java security policy file used for StarRocks UDFs

starrocks-java.yaml

StarRocks CN component
cn.conf
Parameter Description Default value

be_port

Port used by the CN component for communication with other StarRocks components

19060

webserver_port

HTTP port used to access the CN component’s web server

18040

heartbeat_service_port

Port used by the CN component to receive heartbeat messages

19050

brpc_port

Port used for communication with other StarRocks components through the BRPC framework

18060

enable_https

Enables HTTPS for the CN component’s web server

false

ssl_certificate_path

Path to the SSL certificate file used for HTTPS connections

 — 

ssl_private_key_path

Path to the private key file used for HTTPS connections

 — 

starlet_port

Port used by the Starlet service for communication with the CN component

19070

storage_root_path

Root directory for storing data on the CN node

/var/lib/starrocks/cn-storage

starlet_cache_dir

Directory used by Starlet for storing cached data

/var/lib/starrocks/cn-storage/starlet_cache

sys_log_dir

Directory for storing CN component logs

/var/log/starrocks/cn

priority_networks

Specifies the network addresses or subnets that the CN component should prefer for network communication

 — 

spill_local_storage_dir

Directory used for storing intermediate data spilled to local storage during query execution

 — 

JAVA_OPTS

Java Virtual Machine options used by the CN component

 — 

kerberos_principal

Kerberos principal used by the CN component for authentication

 — 

kerberos_keytab

Path to the keytab file used for Kerberos authentication

 — 

kerberos_relogin_check_interval_second

Interval, in seconds, at which the CN component checks whether the Kerberos credentials need to be renewed

60

Custom cn.conf
Parameter Description Default value

Add parameter

In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file cn.conf

 — 

Other
Parameter Description Default value

cn-env.sh

Script that sets environment variables before the StarRocks CN startup

 — 

Enable custom ulimits

Applies a custom limits.d file for the CN process (open files, max processes, etc.)

disabled

StarRocks FE component
fe.conf
Parameter Description Default value

meta_dir

Directory used to store FE metadata

/var/lib/starrocks/fe-meta

sys_log_dir

Directory for storing FE component logs

/var/log/starrocks/fe

audit_log_dir

Directory for storing audit logs

/var/log/starrocks/fe

http_port

HTTP port used to access the FE web server

18030

enable_https

Enables or disables HTTPS for the FE web server

false

https_port

HTTPS port used by the FE web server

18443

rpc_port

Port used for RPC communication between FE nodes

19020

query_port

MySQL protocol port used to connect to the FE and submit SQL queries

19030

edit_log_port

Port used for communication between FE nodes to replicate edit logs

19010

cloud_native_meta_port

Port used for communication with the cloud-native metadata service

6090

priority_networks

Specifies the network addresses or subnets that the FE component should prefer for network communication

 — 

run_mode

Specifies the StarRocks deployment mode

shared_data

enable_load_volume_from_conf

Enables loading storage volume configuration from the FE configuration file

true

enable_hadoop_impersonation

Enables Hadoop impersonation mechanism

true

cloud_native_storage_type

Specifies the type of shared storage used by the StarRocks cluster

HDFS

cloud_native_hdfs_url

Specifies the HDFS URL used as shared storage

hdfs://adh/starrocks

JAVA_OPTS

Java Virtual Machine options used by the FE component

 — 

kerberos_principal

Kerberos principal used by the FE component for authentication

 — 

kerberos_keytab

Path to the keytab file used for Kerberos authentication

 — 

kerberos_relogin_check_interval_second

Interval, in seconds, at which the FE component checks whether the Kerberos credentials need to be renewed

60

Custom fe.conf
Parameter Description Default value

Add parameter

In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file fe.conf

 — 

Other
Parameter Description Default value

fe-env.sh

Script that sets environment variables before the StarRocks FE startup

 — 

Enable custom ulimits

Applies a custom limits.d file for the FE process (open files, max processes, etc.)

disabled

Found a mistake? Seleсt text and press Ctrl+Enter to report it